STIGQter STIGQter: STIG Summary: IBM WebSphere Liberty Server Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Apr 2026:

The WebSphere Liberty Server must install security-relevant software updates within the time period directed by an authoritative source.

DISA Rule

SV-250349r1137612_rule

Vulnerability Number

V-250349

Group Title

SRG-APP-000456-AS-000266

Rule Version

IBMW-LS-001170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Obtain WebSphere Liberty product security and patch support at http://www-01.ibm.com/support/docview.wss?uid=swg27009661.

Run the productInfo validate command to validate the MD5 checksum file for server installation and each feature.

If a feature is not valid, the command outputs an error and lists the manifest file for the affected feature. The following example validates the features for the current installation and outputs the results to the validate.txt file:

productInfo validate --output=/tmp/validate.txt

Check Contents

Use the "productInfo(.bat/.sh) version" command to determine the WebSphere version. Review the patch level and fix pack.

Review the latest fixpacks at: http://www-01.ibm.com/support/docview.wss?uid=swg27009661 and determine if the system is operating at the latest patch level.

If the most recent patches/fix packs have not been applied, this is a finding.

Vulnerability Number

V-250349

Documentable

False

Rule Version

IBMW-LS-001170

Severity Override Guidance

Use the "productInfo(.bat/.sh) version" command to determine the WebSphere version. Review the patch level and fix pack.

Review the latest fixpacks at: http://www-01.ibm.com/support/docview.wss?uid=swg27009661 and determine if the system is operating at the latest patch level.

If the most recent patches/fix packs have not been applied, this is a finding.

Check Content Reference

M

Target Key

5424